ZeroHour

CVE-2024-50337

PoC
CVSS 3.1
5.3 medium
EPSS
<1%p25
Published
()
Modified
Description

Chamilo is a learning management system. Prior to version 1.11.28, the OpenId function allows anyone to send requests to any URL on server's behalf, which results in unauthenticated blind SSRF. This issue has been patched in version 1.11.28.

Vendors
chamilo
Products
chamilo lms
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.